Patch
Curated coverage and analysis in this editorial area.

LiteSpeed cPanel: Two CVEs Added to KEV Catalog, Shared Hosting at Risk
CISA adds two distinct LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog: root privilege escalation on shar…

ZDI-26-356: Apache Reverse Proxy Betrayed by AJP Backend
CVE-2026-34032 in mod_proxy_ajp lets a compromised AJP backend read out of bounds, with potential escalation to RCE via vulnerability…

Adobe Acrobat Reader: UAF in Annotation Parser Enables RCE via Malicious PDF
CVE-2026-27220: use-after-free in Adobe Acrobat Reader DC's Annotation parser, CVSS 7.8. Patch available, no known in-the-wild exploit…

ZDI-26-358: XSS in Allegra with a Classification Anomaly
Trend Micro's Zero Day Initiative published advisory ZDI-26-358 detailing an XSS flaw in Allegra's downloadAttachment method. The advi…

X.Org Server: Root LPE via XkbSetCompatMap; Patch Released
CVE-2026-33999 in X.Org Server enables local privilege escalation to root. Discovered by ZDI, the fix follows a coordinated disclosure…

CVE-2026-11645: Google Patches Fifth Chrome Zero-Day of 2026
Google has released a critical patch for CVE-2026-11645, a zero-day vulnerability in Chrome's V8 engine. With an exploit active in the…

ZDI-26-360: RCE Vulnerability in MATE’s Atril Document Viewer Patched in Version 1.26.4
A heap-based buffer overflow in the Atril EPUB parser (MATE Desktop) allows for remote code execution. The vulnerability is addressed…

ASUS MyASUS: SYSTEM Privilege Escalation Disclosed After 98 Days, Patch Link Remains Circular
CVE-2026-7480: A local privilege escalation vulnerability in MyASUS allows attackers to gain SYSTEM rights. While ASUS has issued an u…

Kemp LoadMaster: Critical Pre-Auth RCE (CVSS 9.8) Triggers Urgent Patching
Progress Software has released a critical patch for Kemp LoadMaster following the coordinated disclosure of three pre-authentication R…

CVE-2026-3886: QEMU virtio-gpu Integer Overflow Enables Guest-to-Host Escape
An integer overflow in QEMU’s virtio-gpu driver allows local privilege escalation from guest to host with a CVSS score of 8.8. The ups…

ZDI-26-336: X.Org Bug Exposes Sensitive Data, Enables Root Escalation
An out-of-bounds (OOB) read in X.Org Server’s CheckKeyActions allows local users to disclose sensitive memory. While the CVSS 6.1 scor…

Adobe USD Plugin: GLTF Heap Overflow Enables Remote Code Execution
Adobe patches CVE-2026-48292, a CVSS 7.8 heap overflow in the usdGltf plugin. While no in-the-wild exploits are reported, 3D productio…